GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Open service 13.225.239.51:443 · staging-test.frec.com
2026-01-23 01:18
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Date: Fri, 23 Jan 2026 01:18:36 GMT x-dns-prefetch-control: on x-xss-protection: 0 content-security-policy: default-src 'self'; frame-src 'self' https://bid.g.doubleclick.net https://*.google.com https://td.doubleclick.net https://www.googletagmanager.com https://www.youtube.com https://jobs.ashbyhq.com; frame-ancestors 'self' https://*.typeform.com https://feedback-pa.clients6.google.com https://frec.com https://td.doubleclick.net https://www.youtube.com; script-src 'self' https://*.browser-intake-datadoghq.com https://*.google.com https://*.googleapis.com https://*.googletagmanager.com https://analytics.tiktok.com https://bid.g.doubleclick.net https://connect.facebook.net https://googleads.g.doubleclick.net https://static.ads-twitter.com https://td.doubleclick.net https://www.facebook.com https://www.google-analytics.com https://www.googleadservices.com https://js.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hsadspixel.net https://js.hscollectedforms.net https://forms.hscollectedforms.net https://jobs.ashbyhq.com/frec/ 'unsafe-inline' 'unsafe-eval'; child-src 'self' blob: https://*.typeform.com https://td.doubleclick.net/ https://www.youtube.com https://staging-test.frec.com; style-src 'self' 'unsafe-inline'; connect-src 'self' https://*.amplitude.com https://*.analytics.google.com https://*.browser-intake-datadoghq.com https://*.frec.com https://*.google-analytics.com https://*.google.com https://*.googleapis.com https://*.googleadservices.com https://*.googlesyndication.com https://*.googletagmanager.com https://*.launchdarkly.com https://ads-api.twitter.com https://ads-twitter.com https://adservice.google.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://analytics.twitter.com https://browser-intake-datadoghq.com https://connect.facebook.net https://google.com https://www.facebook.com https://api.hubapi.com https://forms.hscollectedforms.net https://static.hsappstatic.net https://jobs.ashbyhq.com/frec/ ; img-src 'self' https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.com https://*.google.co.in https://*.googletagmanager.com https://*.wp.com https://ads-api.twitter.com https://ads-twitter.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://analytics.twitter.com https://client-logos.plaid.com https://connect.facebook.net https://google.com https://googleads.g.doubleclick.net https://media.frec.com https://t.co https://wpfiles.frec.com https://freccom.blog https://www.facebook.com https://www.fbcdn.net https://www.googleadservices.com https://cdn.yodlee.com https://forms.hsforms.com https://track.hubspot.com https://securitylogos.frec.com data:; font-src 'self'; media-src 'self' https://media.frec.com; referrer-policy: strict-origin-when-cross-origin strict-transport-security: max-age=63072000; includeSubDomains; preload x-content-type-options: nosniff X-Cache: Miss from cloudfront Via: 1.1 519805cbcdac9c5e896d5aaf823076b6.cloudfront.net (CloudFront) X-Amz-Cf-Pop: BRU50-P2 Alt-Svc: h3=":443"; ma=86400 X-Amz-Cf-Id: UZLk80AtqvgQmKVaU_oYNkh8qk5lPqWL4uUtoDBpVLUMm7MStVY0KA==
Open service 13.225.239.51:443 · staging-test.frec.com
2026-01-09 10:13
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Date: Fri, 09 Jan 2026 10:13:39 GMT x-dns-prefetch-control: on x-xss-protection: 0 content-security-policy: default-src 'self'; frame-src 'self' https://bid.g.doubleclick.net https://*.google.com https://td.doubleclick.net https://www.googletagmanager.com https://www.youtube.com https://jobs.ashbyhq.com; frame-ancestors 'self' https://*.typeform.com https://feedback-pa.clients6.google.com https://frec.com https://td.doubleclick.net https://www.youtube.com; script-src 'self' https://*.browser-intake-datadoghq.com https://*.google.com https://*.googleapis.com https://*.googletagmanager.com https://analytics.tiktok.com https://bid.g.doubleclick.net https://connect.facebook.net https://googleads.g.doubleclick.net https://static.ads-twitter.com https://td.doubleclick.net https://www.facebook.com https://www.google-analytics.com https://www.googleadservices.com https://js.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hsadspixel.net https://js.hscollectedforms.net https://forms.hscollectedforms.net https://jobs.ashbyhq.com/frec/ 'unsafe-inline' 'unsafe-eval'; child-src 'self' blob: https://*.typeform.com https://td.doubleclick.net/ https://www.youtube.com https://staging-test.frec.com; style-src 'self' 'unsafe-inline'; connect-src 'self' https://*.amplitude.com https://*.analytics.google.com https://*.browser-intake-datadoghq.com https://*.frec.com https://*.google-analytics.com https://*.google.com https://*.googleapis.com https://*.googleadservices.com https://*.googlesyndication.com https://*.googletagmanager.com https://*.launchdarkly.com https://ads-api.twitter.com https://ads-twitter.com https://adservice.google.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://analytics.twitter.com https://browser-intake-datadoghq.com https://connect.facebook.net https://google.com https://www.facebook.com https://api.hubapi.com https://forms.hscollectedforms.net https://static.hsappstatic.net https://jobs.ashbyhq.com/frec/ ; img-src 'self' https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.com https://*.google.co.in https://*.googletagmanager.com https://*.wp.com https://ads-api.twitter.com https://ads-twitter.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://analytics.twitter.com https://client-logos.plaid.com https://connect.facebook.net https://google.com https://googleads.g.doubleclick.net https://media.frec.com https://t.co https://wpfiles.frec.com https://freccom.blog https://www.facebook.com https://www.fbcdn.net https://www.googleadservices.com https://cdn.yodlee.com https://forms.hsforms.com https://track.hubspot.com https://securitylogos.frec.com data:; font-src 'self'; media-src 'self' https://media.frec.com; referrer-policy: strict-origin-when-cross-origin strict-transport-security: max-age=63072000; includeSubDomains; preload x-content-type-options: nosniff X-Cache: Miss from cloudfront Via: 1.1 05ef36e101d185586daa8fc331b01c84.cloudfront.net (CloudFront) X-Amz-Cf-Pop: BRU50-P2 Alt-Svc: h3=":443"; ma=86400 X-Amz-Cf-Id: 26W6DAjIIIFvgguG58w3c-Yi3LSZaHWE11_zPEHp7K3clJCF9SUUaA==
Open service 13.225.239.51:443 · staging-test.frec.com
2025-12-23 09:31
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Date: Tue, 23 Dec 2025 09:31:11 GMT x-dns-prefetch-control: on x-xss-protection: 0 content-security-policy: default-src 'self'; frame-src 'self' https://bid.g.doubleclick.net https://*.google.com https://td.doubleclick.net https://www.googletagmanager.com https://www.youtube.com https://jobs.ashbyhq.com; frame-ancestors 'self' https://*.typeform.com https://feedback-pa.clients6.google.com https://frec.com https://td.doubleclick.net https://www.youtube.com; script-src 'self' https://*.browser-intake-datadoghq.com https://*.google.com https://*.googleapis.com https://*.googletagmanager.com https://analytics.tiktok.com https://bid.g.doubleclick.net https://connect.facebook.net https://googleads.g.doubleclick.net https://static.ads-twitter.com https://td.doubleclick.net https://www.facebook.com https://www.google-analytics.com https://www.googleadservices.com https://js.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hsadspixel.net https://js.hscollectedforms.net https://forms.hscollectedforms.net https://jobs.ashbyhq.com/frec/ 'unsafe-inline' 'unsafe-eval'; child-src 'self' blob: https://*.typeform.com https://td.doubleclick.net/ https://www.youtube.com https://staging-test.frec.com; style-src 'self' 'unsafe-inline'; connect-src 'self' https://*.amplitude.com https://*.analytics.google.com https://*.browser-intake-datadoghq.com https://*.frec.com https://*.google-analytics.com https://*.google.com https://*.googleapis.com https://*.googleadservices.com https://*.googlesyndication.com https://*.googletagmanager.com https://*.launchdarkly.com https://ads-api.twitter.com https://ads-twitter.com https://adservice.google.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://analytics.twitter.com https://browser-intake-datadoghq.com https://connect.facebook.net https://google.com https://www.facebook.com https://api.hubapi.com https://forms.hscollectedforms.net https://static.hsappstatic.net https://jobs.ashbyhq.com/frec/ ; img-src 'self' https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.com https://*.google.co.in https://*.googletagmanager.com https://*.wp.com https://ads-api.twitter.com https://ads-twitter.com https://analytics.tiktok.com https://analytics.twitter.com https://client-logos.plaid.com https://connect.facebook.net https://google.com https://googleads.g.doubleclick.net https://media.frec.com https://t.co https://wpfiles.frec.com https://freccom.blog https://www.facebook.com https://www.fbcdn.net https://www.googleadservices.com https://cdn.yodlee.com https://forms.hsforms.com https://track.hubspot.com https://securitylogos.frec.com data:; font-src 'self'; media-src 'self' https://media.frec.com; referrer-policy: strict-origin-when-cross-origin strict-transport-security: max-age=63072000; includeSubDomains; preload x-content-type-options: nosniff X-Cache: Miss from cloudfront Via: 1.1 39fec84b1572a459dc64d17fa6b9ede8.cloudfront.net (CloudFront) X-Amz-Cf-Pop: BRU50-P2 Alt-Svc: h3=":443"; ma=86400 X-Amz-Cf-Id: -G5vIUlDzp-CmrfKWlGhAiZ-ZRRJYhahh8o4Gg_y3Z241hsnPdp5xw==